paper-slides
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bash(*)tool to perform system-level operations, including symlinking files, runninglatexmk/pdflatexfor compilation, and executing Python scripts. This broad access is necessary for its function but increases the impact of potential command injection if input parameters are not properly sanitized. - [DYNAMIC_EXECUTION]: In Phase 7, the skill dynamically generates a Python script (
slides/generate_pptx.py) and executes it usingpython3. While intended to facilitate PowerPoint export, runtime script generation and execution is a high-risk pattern that can be exploited to run arbitrary code if the generation logic is influenced by malicious input data. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as it ingests untrusted content from LaTeX files (
paper/sections/*.tex) and potentially external style references. - Ingestion points: Reads local
.texfiles and external sources via the--style-refargument. - Boundary markers: The instructions do not specify the use of clear delimiters or 'ignore' instructions when processing this content.
- Capability inventory: The skill has
Bash(*)access, file write capabilities, and the ability to execute generated Python code. - Sanitization: There is no mention of escaping or sanitizing the content extracted from the paper before it is used to generate slides or scripts.
- [EXTERNAL_DOWNLOADS]: The
STYLE_HELPERlogic (extract_paper_style.py) accepts HTTP(S) URLs and arXiv IDs as sources. This results in the fetching of external, potentially untrusted content into the skill's processing pipeline.
Audit Metadata